System and method for mitigating denial of service attacks - Patents.com

By employing router identifiers to detect spoofed traffic in communication networks, the method addresses the challenge of DDoS attacks, ensuring legitimate traffic is prioritized and network components are protected.

JP2025515679APending Publication Date: 2025-05-20CENTURYLINK INTELLECTUAL PROPERTY LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024565372
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-09
Filing Date
2023-04-25
Publication Date
2025-05-20

AI Technical Summary

Technical Problem

Existing communication networks face challenges in mitigating denial of service (DoS) and distributed denial of service (DDoS) attacks, particularly with connectionless protocols like UDP, as malicious actors spoof source IP addresses to overwhelm network components, making it difficult to identify and counter these attacks effectively.

Method used

Utilizing router identifiers to track ingress routers and compare them against expected distributions to detect spoofing, initiating threat mitigation actions such as filtering or redirecting suspicious traffic through scrubbing centers.

Benefits of technology

Effectively identifies and counters DDoS attacks by ensuring legitimate traffic is prioritized, reducing the impact on network components and maintaining service availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025515679000001_ABST
    Figure 2025515679000001_ABST
Patent Text Reader

Abstract

Examples of the present disclosure relate to systems and methods for using router identifier information to mitigate denial of service attacks in an autonomous system (AS). Each router in an AS may be assigned a router identifier (ID) that is unique to the AS, which may be changed periodically. An ingress router that first receives a packet within a particular AS may insert its router ID into the packet. A threat intelligence system may sample packets of traffic received by the AS and examine the inserted ingress router IDs when making a threat determination. If the distribution of detected ingress router IDs from the sampled packets does not match the expected distribution of ingress router IDs, one or more threat mitigation actions may be initiated.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] This application claims the benefit of U.S. Provisional Patent Application No. 63 / 339,736, filed May 9, 2022, entitled “Systems and Methods for Mitigating Denial of Services Attacks,” which is incorporated by reference herein in its entirety.

[0002] One or more aspects according to the present disclosure relate to denial of service attacks in communication networks, and more particularly, to using router identifiers to mitigate distributed denial of service attacks. [Background technology]

[0003] Communications networks are becoming increasingly complex. For example, large communications networks may process millions of queries (or more) per second. Malicious actors regularly attempt to circumvent communications network security measures and / or cause communications network failures. For example, denial of service (DoS) and distributed denial of service (DDoS) attacks have become common. DDoS attacks attempt to overwhelm a network component (e.g., a domain name system (DNS) server) or application by flooding the network component or application with excessive requests in an attempt to overload the network, network component, or application and prevent legitimate requests from being fulfilled. In a DDoS attack, the incoming traffic that floods a victim's network component or application may originate from different sources. In this scenario, simply blocking a single source may not be enough to stop the attack.

[0004] Identifying and mitigating DDoS attacks can be more difficult with connectionless protocols such as the User Datagram Protocol (UDP) used by domain name servers (DNS) and the QUIC UDP Internet Connection Protocol (or the transport layer protocol of Hypertext Transport Protocol (HTTP) 3.0).

[0005] The above information disclosed in this Background section is intended solely to enhance a reader's understanding of the present disclosure and, as such, it may include information that does not constitute prior art. Summary of the Invention

[0006] One example of the present disclosure relates to a method that includes receiving traffic information for a first autonomous system, where the traffic information includes: router identifier information identifying at least one ingress router that receives traffic in the first autonomous system; and identification information of a source of the traffic. In an example, the method also includes determining whether the router identifier information matches expected ingress router information for the source of the traffic. In an example, the method further includes initiating a threat mitigation action based at least in part on a determination that the router identifier information does not match the expected ingress router information for the source of the traffic.

[0007] In another aspect, the present disclosure relates to a system comprising at least one processor and a memory operatively connected to the at least one processor and storing instructions that, when executed by the at least one processor, cause the system to perform a method, the method comprising receiving traffic information for a first autonomous system, the traffic information including router identifier information identifying at least one ingress router receiving traffic in the first autonomous system and an identification information of a source of the traffic. In an example, the method also includes determining whether the router identifier information matches expected ingress router information for the source of the traffic. In an example, the method further includes initiating a threat mitigation action based at least in part on a determination that the router identifier information does not match the expected ingress router information for the source of the traffic.

[0008] In another aspect, the disclosure relates to a method that includes receiving traffic information for a first autonomous system, where the traffic information includes: router identifier information identifying at least one ingress router that receives traffic in the first autonomous system; and an identification of a source of the traffic. In an example, the method also includes determining whether the router identifier information matches expected ingress router information for the source of the traffic by: extracting the router identifier information from a plurality of sampled packets received by the first autonomous system; determining from the router identifier information a distribution of ingress routers for the traffic over a period of time; and determining an expected distribution of ingress routers for the period of time based on historical data. In an example, the method also includes initiating a threat mitigation action based at least in part on a determination that the router identifier information does not match the expected ingress router information for the source of the traffic.

[0009] These and other features, aspects, and advantages of the disclosed examples will become more fully understood when considered in conjunction with the following detailed description, the appended claims, and the accompanying drawings, in which: Of course, the actual scope of the invention is defined by the appended claims. [Brief description of the drawings]

[0010] Non-limiting and non-exhaustive examples of the present embodiments are described with reference to the following figures, in which like reference numerals refer to like parts throughout the various views unless otherwise specified.

[0011] [Figure 1] 1 is a block diagram of an exemplary networking environment for mitigating DoS attacks, according to an example.

[0012] [Diagram 2] 1 is a block diagram of a threat intelligence system for mitigating DoS attacks, according to an example.

[0013] [Figure 3A] 1 is a flow diagram of a process for processing a data packet, according to an example.

[0014] [Figure 3B] FIG. 13 is a flow diagram of a process for making a threat determination, according to an example.

[0015] [Figure 4] FIG. 1 is a flow diagram of a process for router ID allocation and reassignment, according to an example.

[0016] [Diagram 5] FIG. 2 is a block diagram of a computing device, according to an example. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0017] Hereinafter, exemplary embodiments will be described in more detail with reference to the accompanying drawings, in which like reference numbers refer to like elements throughout. However, the present disclosure may be embodied in various different forms and should not be construed as being limited to only the embodiments shown herein. Rather, these embodiments are provided as examples so that the present disclosure will be thorough and complete, and will fully convey aspects and features of the present disclosure to those skilled in the art. Thus, processes, elements, and techniques that are not necessary for those skilled in the art to understand the aspects and features of the present disclosure may not be described. Unless otherwise noted, like reference numbers refer to like elements throughout the accompanying drawings and written description, and therefore the description may not be repeated. Additionally, in the drawings, the relative sizes of elements, layers, and regions may be exaggerated and / or simplified for clarity.

[0018] DoS and DDoS attacks (collectively referred to herein as DoS attacks) that attempt to overwhelm an organization's network components (e.g., Domain Name System (DNS) servers, web or content servers, etc.) have become common. When a DDoS attack is launched, numerous attacking machines may send a flood of requests or requests specifically tailored for a service to a target service that may overwhelm the target service and degrade its ability to service legitimate requests if appropriate measures are not taken. As used herein, a service may include a computing device or collection of computing devices that perform a computing service, such as, but not limited to, a domain name service, a content delivery service, a website hosting service, etc. In a DDoS attack, an attacking machine may simultaneously spoof multiple IP addresses to hide the attacker's location, which may make the attack difficult to mitigate.

[0019] In a general sense, examples of the present disclosure relate to systems and methods for using router identifier information (e.g., a particular router identifier (ID)) to mitigate network DoS attacks in an autonomous system (AS). An AS may include routers whose IP address prefixes and routing policies are under common administrative control. In one example, each router in an AS is assigned a router identifier (ID) that may be different from either the router's IP address or media access control (MAC) address. At a minimum, the assigned router ID may be unique to routers within the same AS. In an example, router IDs may be assigned upon configuration of the router and periodically reassigned upon detection of criteria such as router ID expiration.

[0020] In an example, the ingress router that first receives the packet within a particular AS (which is often the router that is logically closest to the source sending the data packet) receives the packet and inserts its router ID into the packet. The threat intelligence system may receive traffic information about traffic received by a particular AS, where the traffic information includes both router identifier information (e.g., the router identifier) ​​and identification information of the source of the traffic.

[0021] For example, a threat intelligence system may sample packets of traffic received by an AS and examine the sampled packets and the inserted router IDs and source IP addresses of such packets when making a threat determination. As used herein, traffic includes electronic messages or portions of electronic messages (e.g., Internet Protocol (IP) packets) sent or received by one or more networks or network systems. In one example, a threat intelligence system randomly or periodically samples packets to determine trends, maintain threat measures, and / or perform statistical evaluations of detected and expected ingress router IDs. For example, a threat intelligence system may randomly sample packets purporting to be from a particular source IP address or source AS to identify an ingress router (e.g., peering point / ingress point) router of the AS receiving the packet. In an example, the distribution of router IDs detected from sampled packets may not match the expected distribution of ingress router IDs, for example, by a threshold deviation. For example, when a randomly sampled packet is sent by a peer AS (e.g., a source AS), the packet is expected to be received by one of a particular ingress router, or set of routers, associated with the peering point of the peer AS. If the source IP address is spoofed by an attacker to make the packet appear to be coming from the peer AS when in fact the packet is coming from outside the peer AS, the packet may be received by a router other than the expected ingress router at the peering point. In this case, the distribution of router IDs in the packet may differ from the expected distribution of router IDs for routers at the peering point, and such information may be used by a threat intelligence system to determine if a threat condition has been met.

[0022] In one example, the threat intelligence system initiates a threat mitigation action in response to detecting a threat. For example, the threat intelligence system may have the threat mitigation system scrub traffic deemed suspicious. In some examples, an ingress point router of an AS may be instructed to reject packets from a peer AS that results in a spoofed source IP address and / or a mismatch between the expected and actual distribution of ingress point routers. Other threat mitigation actions may also be taken.

[0023] 1 is a block diagram of an exemplary networking environment for mitigating DoS attacks, according to one example. The networking environment may include any type of telecommunications network that utilizes IP addresses to connect one or more components of the network.

[0024] In one example, the networking environment includes a first AS 100 and a second AS 102. The first AS 100 and the second AS 102 may exchange packets with each other via a link 104. Each AS 100, 102 may be under a separate administrative domain, such as a particular Internet Service Provider (ISP), a particular corporation, or some other organization. Each AS may be assigned one or more ranges of IP addresses, which are then advertised to each other and to other autonomous systems and / or networks, e.g., the Internet, to enable packets containing the IP addresses to be directed to the corresponding destination AS. Each AS may further be assigned a unique AS number by a registry organization, e.g., the American Registry for Internet Numbers.

[0025] In one example, the first AS 100 includes multiple routers 106a-106e (collectively referred to as 106) that share the same AS number. One or more of the routers may provide an ingress point (also referred to as an ingress or peering point) to the first AS 100. For example, router R1 106a may be an ingress point for receiving packets 108 from the second AS 102 that are destined for one or more target servers 110a, 110b (collectively referred to as 110). In an example, router R1 106a may be specifically designated as the ingress router for packets from AS 102. In another example, R1 may naturally act as the ingress router for the majority of packets from AS 102 (due to routing protocols) due to its geographic or logical proximity to router R6 113 in AS 102. In an example, R3 106c may also receive some traffic from AS 102 during normal operation (e.g., due to load management on router R1 106a). The target server 110 may be configured to provide one or more target services. The one or more target services may include, for example, a Domain Name System (DNS) service, a content delivery service, and / or the like. As used herein, an ingress router refers to the first router for receiving traffic within an AS.

[0026] A packet 108 sent from the second AS 102 to the first AS 100 may include a source address 128 and a destination address 130. For example, a packet sent by server S3 112 to server S2 110b may include the IP address of server S3 112 as the source address 128 and may further include the IP address of server S2 110b as the destination address 130. The packet 108 may also identify the packet as originating from the AS 102. In another example, the AS 100 may be able to determine from the source address 128 that the packet 108 originated from (or is said to originate from) the AS 102.

[0027] An ingress router in the first AS 100 (e.g., router R1 106a) may receive a packet from a router in the second AS 102 (e.g., router R6 113), determine the destination / target IP address of the traffic (e.g., the IP address of server S2 110b), determine a route for the traffic within the AS 100, and forward the packet to the target server S2 110b based on the determined route. The packet may traverse one or more of the other routers in the first AS 100 (e.g., router R2 106b and router R4 106d) before reaching the target (e.g., server 110b).

[0028] In some cases, the attacker 114 may send malicious requests directed to the first AS 100 in an attempt to overload the network components or applications of the first AS 100 and prevent legitimate requests from being fulfilled. The malicious requests may be in the form of a DoS attack, including a flood of requests or requests specifically tailored for a service aimed at overwhelming the first AS (or a particular service of the first AS 100, e.g., a service provided by server S2 110b). In one example, the malicious requests may be sent in a malicious packet 116 that spoofs the IP source address 118 by inserting the IP address of server S3 112 instead of the real IP address 120 of the attacker 114. Thus, the malicious packet 116 appears to originate from the second AS 102 (e.g., because the AS 100 associates the spoofed IP source address with the AS 102).

[0029] Continuing with this example, the malicious packet 116 is received by router R5 106e according to a route selected by a separate routing protocol or route table maintained or utilized by the attacker device 114. In response to receiving the packet, router R5 106e inserts a router ID into the packet that is uniquely assigned to router R5 106e. As discussed further herein, the routers 106 in the first AS 100 are assigned router IDs that are unique to them at least within the AS 100. One or more of the routers 106 (e.g., ingress routers R1 106a, R3 106c, and R5 106e) may be configured to insert their assigned routing IDs upon receiving a packet from outside the AS 100. For example, router R5 106e is configured to receive the malicious packet 116 and insert its router ID 122 (e.g., R5) into the packet, and router R1 106a is configured to receive the packet 108 and insert its router ID 124 (e.g., R1) into the packet. In some examples, one or more other intervening routers (e.g., R2 and R4) may also insert their respective router IDs along the route within the AS 100.

[0030] In one example, the router ID is inserted into a predefined field 123, 125, 127 in the header of the data packet 116, 108. The predefined field can be, for example, the "options" field for an IPv4 data packet.

[0031] In some examples, a router in the second AS 102 (e.g., router R6 113) may insert its router ID 131 (e.g., R6) into the packet 108 before sending the packet to the first AS 100. A router in the first AS 100 receiving the packet (e.g., router R1 106a) may append its router ID 124 (e.g., R1) to the router ID 131 (e.g., R6) already present in the packet. In other examples, a router in the first AS 100 receiving the packet (e.g., router R1 106a) may insert its router ID 124 (e.g., R1) into the packet in place of the router ID (e.g., R6) already present in the packet. In some examples, the spoofed packet 116 may also include a spoofed router ID of router 113 (R6). In other examples, the spoofed packet 116 may not include a router ID for what is purported to be the exit router of the source AS.

[0032] In one example, the first AS 100 further includes a threat intelligence system 126. The threat intelligence system 126 may analyze the traffic information to identify threats to the AS 100. In an example, the traffic information includes both router identifier information (e.g., router identifiers, or information from which a router identifier can be derived) and identification information of a source of the traffic. The traffic information may be obtained, for example, from various servers 110 and / or routers 106 of the first AS 100. In one example, the threat intelligence system 126 is configured to sample packets received by the servers 110 and / or routers 106 at a given rate (e.g., 1 in 100) to identify threats. The threat intelligence system 106 may compare the router identifier information from the sampled packets to expected ingress router information. For example, during a particular sampling, the threat intelligence system 126 may compare the ingress router ID inserted in the packet 108', 116' against the expected router ID to determine if there is a mismatch of the router ID. In a simple example, the threat intelligence system 126 may determine for the sampled packet: (a) what is referred to as the source IP address and / or source AS; (b) the first router ID (e.g., 122, 124) inserted in the packet after ingress into the AS 100; and (c) the expected ingress router ID for the source IP address and / or source AS. In some examples, the expected ingress router information may include the most likely router ID (e.g., based on historical data) for the source IP address and / or source AS. For example, a single most likely ingress router ID may be determined as the expected ingress router information, and if there is a mismatch between the expected ingress router ID and the ingress router ID in the sampled packet, the threat amount for the particular source IP address and / or source AS may be incremented. In some examples, the threat amount may also be decremented if a period of time passes without a mismatch or if there is a match between the expected ingress router ID and the ingress router ID in the sampled packet.The current value of the threat volume for that particular source IP address and / or source AS may then be used as a factor to determine whether a threat has been detected or whether a threat condition currently exists.

[0033] In other examples, the expected ingress router information may include multiple expected ingress router IDs for the source IP address and / or source AS, and a "match" or "mismatch" may be determined more globally. For example, if the traffic load from AS 102 to AS 100 is typically split among multiple ingress routers (e.g., router R1 106a and router R3 106c), a comparison of the actual and expected router IDs may be made based on statistics over a period of time (instead of determining whether a particular ingress router ID in a single packet matches a expected ingress router ID).

[0034] As discussed, the expected ingress router information may depend on historical data. For example, the threat intelligence system 126 may maintain running statistics of router IDs for ingress routers of the AS 100 that receive packets from different ASes (e.g., AS 102). For example, if historically 80% of traffic from the second AS 102 is received at R1 106a, while 20% of the traffic is received at R3 106c, then the distribution of ingress router IDs detected in sampled packets is expected to be similar over a period of time. If the threat intelligence system 126 detects a sudden change in the distribution of received traffic to the ingress routers, or an increase in data packets purported to be received from the second AS 102 with a completely different router ID (e.g., the router ID of R5 106e), the threat intelligence system 126 may determine that the threat profile has been met. In an example where a single most likely ingress router is used as the expected ingress router distribution (e.g., R1 106a), the threat amount may be incremented if a packet from AS 102 is received by a router other than R1 106a. However, because 20% of the traffic is expected based on historical trends to be received by R3 106c, the threat profile may be set such that it is only met if, for example, more than 25 of the last 100 samples. In an example where the expected ingress router distribution includes multiple routers (e.g., in a particular ratio), the threat profile may be set such that it is met if the percentage of traffic ever received by either or both of R1 106a and / or R3 106c fluctuates by more than X%. The threat profile may also be met based on consideration of other factors, such as the total traffic directed to a particular server (e.g., server S2 110b) rising by X% in the last Y minutes, and / or the like.

[0035] In an example, the threat intelligence system 126 may store or have access to other routing information relevant to determining the expected distribution of source IP addresses or router IDs for a purported source AS. For example, the other routing information may include a known peering relationship between AS100 and AS102 (e.g., designated ingress routers R1 106a and R3 106c dedicated to AS102), a known set of source IP addresses assigned to AS102 (so that the source AS can be determined from a purported source IP address of a packet), known load balancing information (e.g., whether an increase in traffic from AS102 to R5 106e is suspicious because a load balancing server recently added router R5 106e to the AS100 / AS102 peering relationship), etc.

[0036] In an example, if a threat is detected, the threat intelligence system may cause mitigation actions to be taken (e.g., if the amount of the threat exceeds a certain threshold, or if traffic purported to be from a particular source IP address or source AS deviates from the expected ingress router distribution by more than a threshold over a measurement period). Mitigation actions may include providing filters, on-demand scrubbers, or other rules or components to mitigate the effects of the identified threat. In this regard, the threat intelligence system 126 may signal the router 106 and / or the server 110 to take threat mitigation steps to attempt to counter the attack. As a non-exclusive example, a filter may be implemented in router R5 106e to drop any packets received with source IP address 118. In other examples, router 106 may be instructed (e.g., by threat intelligence system 126 or another component) to apply filtering rules while a threat (or potential threat) is detected, or to direct all traffic from source IP address 118 and / or AS 102 to one or more scrubbing centers or other scrubbing appliances for further analysis of the traffic. Once a threat is identified, threat mitigation for the identified threat may be applied at or by router 106 and / or other devices within (or external to) AS 100.

[0037] 2 is a block diagram of a threat intelligence system 126 for mitigating DoS attacks, according to an example. The second AS 102 may include a similar threat intelligence system (not shown) for initiating threat mitigation services for the second AS.

[0038] In one example, the threat intelligence system 126 includes a router ID manager 200 and a threat analyzer 202. Although the router ID manager 200 and the threat analyzer 202 are depicted as separate components in Figure 2, one skilled in the art should recognize that these components 200, 202 may be combined into a single component, or one or more of the components may be further subdivided into additional subcomponents, as would be understood by one skilled in the art.

[0039] The router ID manager 200 and the threat analyzer 202 may be hosted on a single device or distributed across multiple devices. For example, the router ID manager 200 and / or the threat analyzer 202 may be hosted on one or more routers 106, servers 110, or other appliances of the first AS 100. In some examples, the services of the router ID manager 200 and / or the threat analyzer 202 may be provided by a third party.

[0040] In one example, the router ID manager 200 is configured to assign a unique router ID to the router 106 in the first AS 100. The router ID manager 200 may store the router ID in a mapping table in association with other identifiers for the router 106, such as the router IP address, MAC address, etc.

[0041] In some examples, router IDs are generated internally by the routers 106 themselves and sent to the router ID manager 200 to generate the mapping table. The routers 106 may send their router IDs in response to a query by the router ID manager 200, for example, when the routers first connect to the AS 100. A query mechanism such as Internet Control Message Protocol version 6 (ICMPv6) may be used to query the routers for their router IDs. The routers 106 may send other information, such as a timestamp of the router ID or other router ID expiration information.

[0042] The router ID may be a numeric value. An initial router ID may be assigned (e.g., randomly) when the router 106 is first provisioned and configured on the AS 100. Router IDs may also be assigned based on router characteristics, such as, for example, the geographic region in which the router is located. For example, a first block of router IDs may be reserved for routers in a first geographic region, and a second block of router IDs may be reserved for routers in a second geographic region. Routers in the first geographic region may then be assigned router IDs from the first block of IDs, and routers in the second geographic region may be assigned router IDs from the second block of IDs.

[0043] In one example, the router ID assigned to a router expires after a certain time or when some other expiry criteria is met. In one example, a timestamp indicating when the router ID was assigned is stored in the mapping table along with the router ID. In one example, the router ID manager 200 periodically checks the mapping table to determine if any router IDs have expired. Upon expiry, the router ID manager 200 assigns (or sends a message to cause the assignment of) a new / different router ID for the router 106. In an example, the change of router ID may help prevent bad actors from further spoofing ingress router ID packets received by the AS 100.

[0044] In one example, the threat analyzer 202 is configured to collect traffic information (e.g., from the server 110 and / or the router 106) and analyze it for indications of malicious traffic. The traffic information may include both information about the traffic and the router ID of the router at the ingress point receiving the traffic. In one example, the threat analyzer samples data packets at a given rate to analyze the packets for threats. For example, if a packet is selected for analysis, the threat analyzer reads from the packet the router ID of the ingress router receiving the packet. The threat analyzer 202 may determine whether the router ID of the ingress router matches expected ingress router information (e.g., the router ID of the router expected to receive the traffic, e.g., from a historical / statistical perspective, given the source IP address). A threat count / volume may be increased in case of a mismatch.

[0045] In one example, the threat volume may be compared to one or more thresholds to determine a particular action to be taken. The threshold may be time-based. For example, the threshold may include a certain number of packets meeting the threshold within a pre-set time window (e.g., the last X minutes). If the threat count exceeds an appropriate threshold, the threat count may be used to trigger one or more mitigation actions. In another example, the threat determination is based on statistically comparing the expected distribution of ingress routers for a particular source IP address or source AS with the distribution detected from sampled packets, e.g., over a period of time.

[0046] Mitigation actions may include providing filters, on-demand scrubbers, routing to a separate scrubbing center, or other rules or components to mitigate the effects of the identified threat. For example, the threat analyzer 202 may signal an appropriate router (e.g., router R5 106e), scrubber, or filtering system to apply one or more mitigation rules. One example of a mitigation rule may be to filter or ignore / drop any data packets that fit the criteria defined by the mitigation rule (e.g., dropping packets with a particular source IP address or source IP addresses associated with the second AS 102). In another example, a mitigation rule may cause a delay in the response to a client query (without dropping the message entirely). Mitigation actions may be implemented for a pre-configured period of time until the conditions causing the mitigation action are remedied or until an administrator of the threat intelligence system 126 determines that the threat mitigation action is no longer necessary, among other options.

[0047] FIG. 3A is a flow diagram of a process. In an example, the process of FIG. 3A may be implemented by one of the routers 106 of the first AS 100 for processing a data packet, according to an example. In another example, the process of FIG. 3A may be implemented by one or more routers 106 in combination with one or more separate threat mitigation devices or services. The process begins with an operation 300 in which traffic (e.g., packet 116 or 108) is received, for example, by one of the routers (e.g., router R5 106e or router R1 106a). The data packet may have, as a source IP address, an IP address of a network component (e.g., S3 112) in the second AS 102.

[0048] In operation 302, a determination is made whether the received packet should be filtered or routed according to the destination IP address. The determination may be based, for example, on rules in a routing table used by the receiving router. If there is no threat or a threat has not yet been detected by the threat intelligence system 126, the routing table may not include rules to filter out the data packet and / or redirect it to a scrubbing center or other threat mitigation device or service. In this case, the receiving router inserts its uniquely assigned router ID into a pre-configured field of the data packet in operation 304. For example, the pre-configured field may be an "options" field in the header of the IPv4 data packet.

[0049] In operation 306, the data packet is routed to the destination address. For example, the packet may be routed to server 110b in AS 100.

[0050] At operation 308, a determination is made whether an update is needed for any filtering information used by one or more routers. For example, the update may be needed in response to a threat determination by the threat intelligence system 126. As discussed, the threat determination may be statistically derived based on the monitored traffic of the first AS 100, or may be based on known peering relationships or load balancing information, among other possibilities. For example, the threat intelligence system 126 may determine that a data packet from a particular IP source address (e.g., IP address 1.2.3.4) and / or a particular AS (e.g., the second AS 102) is malicious based on the monitored traffic. In response to the threat determination, the threat intelligence system 126 may send a signal to one or more routers (e.g., router R5 106e) of the first AS 100 to update their routing tables with filtering rules that, for example, filter out packets from the particular IP source address and / or the particular AS. In other examples, routing tables may be updated to direct traffic from particular IP source addresses and / or particular ASes to one or more scrubbing centers and / or other threat mitigation devices or services.

[0051] In operation 310, the router receiving the signal uses the filtering rules to perform, for example, updates its routing tables.

[0052] Referring again to operation 302, if a determination is made in operation 300 that the received packet should be filtered according to existing filtering rules, the packet may be filtered or ignored in operation 312. In other examples, packets from a particular IP source address and / or a particular AS may be redirected to one or more scrubbing centers and / or other threat mitigation devices or services. Filtering may be performed, for example, by filters, scrubbers, and / or the like provided on a router, or another device in AS 100, or a separate scrubbing center communicatively coupled to AS 100.

[0053] Over time, threats may change (e.g., increase or decrease). For example, if the amount of threats decreases below a certain threshold, it may no longer be necessary to filter packets according to existing filtering rules. In other examples, filtering rules may be modified according to an increase in threats (e.g., packets that were redirected by an initial filtering rule may be dropped at the router in response to detection of an increased threat). Thus, in operation 308, a determination is made as to whether the filtering information used by the router should be updated (e.g., by removing or modifying an existing filtering rule). If the answer is YES, then the update is performed in operation 310.

[0054] 3B is a flow diagram of a process for making a threat determination, according to an example. The process begins and in operation 320, traffic information of incoming packets is received, for example, by the threat intelligence system 126. For example, the traffic information may be collected according to the NetFlow protocol or otherwise. The traffic information may include, for example, source IP address, destination IP address, sending AS number, ingress router ID, timestamp, and / or the like. The traffic information may be obtained, for example, from various servers 110 and / or routers 106 of the first AS 100.

[0055] A determination is made whether a threat has been identified based on the received traffic information in operation 322. In this regard, the threat intelligence system 126 may be configured to sample the traffic information at a given rate (e.g., sample 1 data packet out of 100 received packets) to determine potential threats.

[0056] In one example, the threat determination includes comparing a router ID inserted by a router at the ingress point of the first AS 100 receiving the data packet against an expected ingress router ID. Each inserted router ID may be read from the header of the data packet, for example, along with a timestamp indicating when the router ID was inserted. In an example, the timestamp may be used such that the router ID is considered as a group router ID of a single router that may have changed during the evaluation period. The expected ingress router ID may be determined based on historical data, for example, as described.

[0057] In some examples, the ingress router ID purportedly inserted into each packet from the second AS may be evaluated to determine if it matches the expected ingress router ID for that second AS. If not, the threat amount may be incremented. In other examples, the expected ingress router ID for traffic from the second AS may be evaluated statistically (e.g., the ingress router ID should be distributed in a predictable manner over a set period of time). For example, if historically 80% of traffic from the second AS 102 is received at R1 106a and 20% of traffic from the second AS 102 is received at R3 106c, then the expected router ID distribution for traffic from the second AS may be similar. Other expected distributions of router IDs for traffic from a particular AS are possible and contemplated, including consideration of defined peer placements, load balancing information, etc.

[0058] In one example, a threat may be detected when, for example, the threat intelligence system 126 detects a mismatch between the inserted router ID and the expected router ID within a given time period. For example, the threat intelligence system 126 may identify a threat as present when the threat volume increments above a certain threshold, or when a certain percentage of sampled packets in the last X minutes / hours have a mismatch with the most likely ingress router ID, or when the actual distribution of router IDs from sampled packets within a given time period differs from the expected distribution of router IDs by at least a threshold (e.g., a threshold percentage). In an example, the comparison of router identifier information from sampled packets to expected ingress router information may be used as a non-exclusive factor along with other information in determining whether a threat condition exists. For example, third party threat assessments associated with a particular source IP address, an unusual increase in traffic volume to a particular destination IP address, and other information may be used in making a threat determination.

[0059] In some examples, a mismatch between the detected and expected ingress router IDs may be due to the router ID of the expected router being assigned a new router ID upon expiration of the previous router ID. If the expected router ID has expired and the mapping table has not yet been updated, a query (e.g., using an ICMPv6 query mechanism) may be sent to the expected router to obtain an updated router ID. The detected and expected router IDs may then be reevaluated in light of the updated router ID.

[0060] Assuming the router IDs have been updated, if a threat is detected from the collected statistics, a threat mitigation action may be invoked in operation 324. Threat mitigation actions may include, for example, adding filtering rules to signal one or more routers to filter out and / or redirect packets with particular source IP addresses, AR numbers, and / or the like. Other mitigation actions may include delaying responses to client queries without dropping the messages entirely.

[0061] 4 is a flow diagram of a process for router ID allocation and reassignment, according to an example. The process begins with operation 400, where one of the routers 106 is assigned an initial router ID. In examples, the router ID may be assigned by the router ID manager 200 or may be generated by the router itself. In one example, the router ID is selected randomly. In one example, the router ID is selected from a group of router IDs reserved for routers in a particular geographic area. Regardless of the selection mechanism, the selected router ID may be unique to the router, at least within the router's AS.

[0062] In one example, the router ID is stored in a mapping table maintained by router ID manager 200. The router ID may be stored along with timestamp information that may be used to determine if the router ID has expired.

[0063] At operation 402, a determination is made as to whether the router ID has expired. In this regard, the assigned router ID may be configured to expire a certain amount of time after the last assignment by the router 106. This may help reduce the possibility that an attacker may determine the router ID of a particular router and add the router ID to packets during a DoS attack.

[0064] If the router ID has expired, a new router ID is assigned to the router 106 in operation 404. The new router ID may be different from one or more previous router IDs of the router.

[0065] In an example, in operation 406, a mapping table maintained by router ID manager 200 is updated with the new router ID and a timestamp of the new ID. In an example, the updated mapping table of router IDs may be provided to and / or made available to threat intelligence system 126. In combination with the timestamp of when the ingress router ID was inserted into the packet and the timestamp of the validity time of the new router ID, threat intelligence system 126 can determine an expected router ID or router ID distribution for a particular source IP address and / or source AS, as described herein.

[0066] 5 is a block diagram of a computing device 500 according to an example. The computing device 500, or various components and systems of the computing device 500, may be integrated or associated with the routers 106, 113, the servers 110, 112, and the threat intelligence system 126. As shown in FIG. 5, the physical components (e.g., hardware) of the computing device are shown, which may be used to practice various aspects of the present disclosure.

[0067] The computing device 500 may include at least one processing unit 510 and a system memory 520. The system memory 520 may include, but is not limited to, volatile storage (e.g., random access memory), non-volatile storage (e.g., read-only memory), flash memory, or any combination of such memory. The system memory 520 may also include an operating system 530 that controls the operation of the computing device 500, and one or more program modules 540. The program modules 540 may be responsible for collecting or determining event data 550, including endpoint data and / or network data. A number of different program modules and data files may be stored in the system memory 520. The program modules 540, while executing on the processing unit 510, may perform various operations as described above.

[0068] Computing device 500 may also have additional features or functionality. For example, computing device 500 may include additional data storage devices (e.g., removable and / or non-removable storage devices), such as, for example, magnetic disks, optical disks, or tape. These additional storage devices are labeled removable storage 560 and non-removable storage 570.

[0069] Examples of the disclosure may be implemented in electrical circuits including discrete electronic elements, packaged or integrated electronic chips containing logic gates, microprocessor-based circuits, or on a single chip containing electronic elements or a microprocessor. For example, examples of the disclosure may be implemented via a system-on-a-chip (SOC) that may integrate each or many of the components shown in FIG. 5 into a single integrated circuit. Such a SOC device may include one or more processing units, graphics units, communications units, system virtualization units, and various application functions, all of which are integrated (or "burned") onto a chip substrate as a single integrated circuit.

[0070] When operating via a SOC, the functionality described herein may be operated via application specific logic integrated with other components of computing device 500 on a single integrated circuit (chip). The present disclosure may also be implemented using other technologies capable of performing logical operations such as, for example, AND, OR, and NOT, including, but not limited to, mechanical, optical, fluidic, and quantum technologies.

[0071] The computing device 500 may include one or more communication systems 580 that enable the computing device 500 to communicate with other computing devices 595, such as, for example, servers, routers, network devices, client computing devices, etc. Examples of communication systems 580 include, but are not limited to, wireless communication, wired communication, cellular communication, radio frequency (RF) transmitter, receiver, and / or transceiver circuitry, Controller Area Network (CAN) bus, universal serial bus (USB), parallel, serial ports, etc.

[0072] Computing device 500 may also have one or more input devices and / or one or more output devices, shown as input / output devices 590. These input / output devices 590 may include keyboards, sound or voice input devices, haptic devices, touch, force, and / or swipe input devices, displays, speakers, etc. The foregoing devices are examples and others may be used.

[0073] As used herein, the term computer-readable media may include non-transitory computer storage media, which may include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information, such as computer-readable instructions, data structures, or program modules.

[0074] System memory 520, removable storage 560, and non-removable storage 570 are all examples of computer storage media (e.g., memory storage). Computer storage media may include RAM, ROM, electrically erasable read mainas only memory (EEPROM), flash memory, or other memory technology, CD-ROM, digital versatile disk (DVD), or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage, or other magnetic storage devices, or any other article of manufacture usable to store information and accessible by computing device 500. Any such computer storage media may be part of computing device 500. Computer storage media are non-transitory and do not include carrier waves or other propagated or modulated data signals.

[0075] Communication media may be embodied by computer readable instructions, data structures, program modules, or other data in a modulated data signal, such as a carrier wave or other transport mechanism, and includes any information delivery media. The term "modulated data signal" may be described as a signal that has one or more characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, communication media may include wired media, such as a wired network or direct-wired connection, and wireless media, such as acoustic, radio frequency (RF), infrared and other wireless media.

[0076] The terminology used herein is for the purpose of describing particular examples only and is not intended to limit the inventive concepts. Also, unless expressly stated, the examples described herein are not mutually exclusive. Aspects of the examples described herein may be combined in some implementations.

[0077] As used herein, the singular forms "a" and "an" are intended to include the plural forms unless the context clearly indicates otherwise. It will be further understood that the terms "comprise" and / or "comprising" as used herein specify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items. Phrases such as "at least one of" preceding a list of elements modify the entire list of elements and not the individual elements of the list. Furthermore, the use of "may" when describing examples of an inventive concept refers to "one or more examples of the present disclosure." Also, the term "exemplary" is intended to refer to an example or illustration. As used in this specification, the terms "use," "using," and "used" may be considered synonymous with the terms "utilize," "utilizing," and "utilized," respectively.

[0078] While exemplary embodiments of the system and method for mitigating DoS attacks have been specifically described and illustrated herein, many modifications and variations will be apparent to those skilled in the art. It should therefore be understood that the system and method for mitigating DoS attacks constructed in accordance with the principles of the present disclosure may be embodied other than as specifically described herein. The present disclosure is also defined in the following claims and equivalents thereof.

Claims

1. receiving traffic information for a first autonomous system, where the traffic information comprises: router identifier information identifying at least one ingress router receiving traffic in the first autonomous system; and having an identity of a source of said traffic; determining whether the router identifier information matches expected ingress router information for the source of the traffic; and initiating a threat mitigation action based at least in part on a determination that the router identifier information does not match the expected ingress router information for the source of the traffic. A method comprising:

2. determining whether the router identifier information matches the expected ingress router information; extracting the router identifier information from a plurality of sampled packets received by the first autonomous system; determining a distribution of ingress routers for said traffic over a period of time from said router identifier information; and determining an expected distribution of ingress routers during said period based on historical data; The method of claim 1 further comprising:

3. 3. The method of claim 2, wherein the identification of the source of the traffic is a source IP address in each of the plurality of sampled packets.

4. The method of claim 2 or 3, wherein the identification of the source of the traffic is an autonomous system identifier of a second autonomous system.

5. The step of determining whether the router identifier information matches the expected ingress router information comprises: incrementing a threat metric if the router identifier information for any packet of the plurality of packets does not match an expected distribution of ingress routers; and determining whether the threat amount exceeds a threshold; The method of claim 2 or 3, further comprising:

6. The step of determining whether the router identifier information matches the expected ingress router information comprises: determining whether the distribution of ingress routers for the traffic during the period of time differs from the expected distribution of ingress routers for the period of time by at least a threshold value; The method of claim 2 or 3, further comprising:

7. periodically changing the router identifier information for the at least one ingress router to new router identifier information; and updating a router mapping table with the new router identifier information. The method of claim 1 , further comprising:

8. 8. The method of claim 7, wherein the new router identifier information includes an expiration date, the expected ingress router information is determined from the router mapping table, and the router identifier information includes a timestamp indicating when the at least one ingress router received the traffic in the first autonomous system.

9. 8. The method of claim 7, wherein the router identifier information comprises a router identifier that is distinct from either an Internet Protocol (IP) address or a media access control address.

10. 13. A system comprising: At least one processor; and a memory operatively connected to the at least one processor and storing instructions that, when executed by the at least one processor, cause the system to perform a method, the method comprising: receiving traffic information for a first autonomous system, where the traffic information comprises: router identifier information identifying at least one ingress router receiving traffic in the first autonomous system; and including an identity of the source of said traffic; determining whether the router identifier information matches expected ingress router information for the source of the traffic; and initiating a threat mitigation action based at least in part on a determination that the router identifier information does not match the expected ingress router information for the source of the traffic. have A system comprising:

11. determining whether the router identifier information matches the expected ingress router information; extracting the router identifier information from a plurality of sampled packets received by the first autonomous system; determining a distribution of ingress routers for said traffic over a period of time from said router identifier information; and determining an expected distribution of ingress routers during said period based on historical data; The system of claim 10 further comprising:

12. The system of claim 11 , wherein the identification of the source of the traffic is a source IP address in each of the plurality of sampled packets.

13. 13. The system of claim 11 or 12, wherein the identification of the source of the traffic is an autonomous system identifier of a second autonomous system.

14. The step of determining whether the router identifier information matches the expected ingress router information comprises: incrementing a threat metric if the router identifier information for any packet of the plurality of packets does not match an expected distribution of ingress routers; and determining whether the threat amount exceeds a threshold; The system of claim 11 or 12, further comprising:

15. The step of determining whether the router identifier information matches the expected ingress router information comprises: determining whether the distribution of ingress routers for the traffic during the period of time differs from the expected distribution of ingress routers for the period of time by at least a threshold value; The system of claim 11 or 12, further comprising:

16. The method comprises: periodically changing the router identifier information for the at least one ingress router to new router identifier information; and updating a router mapping table with the new router identifier information. The system of claim 10 further comprising:

17. 17. The system of claim 16, wherein the new router identifier information includes an expiration date, the expected ingress router information is determined from the router mapping table, and the router identifier information includes a timestamp indicating when the at least one ingress router received the traffic in the first autonomous system.

18. 17. The system of claim 16, wherein the router identifier information comprises a router identifier that is different from either an Internet Protocol (IP) address or a media access control address.

19. receiving traffic information for a first autonomous system, where the traffic information comprises: router identifier information identifying at least one ingress router receiving traffic in the first autonomous system; and including an identity of the source of said traffic; Whether the router identifier information matches expected ingress router information for the source of the traffic: extracting the router identifier information from a plurality of sampled packets received by the first autonomous system; determining a distribution of ingress routers for the traffic over a period of time from the router identifier information; and determining an expected distribution of ingress routers during said period based on historical data; determining whether initiating a threat mitigation action based at least in part on a determination that the router identifier information does not match the expected ingress router information for the source of the traffic. A method for providing the above.

20. periodically changing the router identifier information for the at least one ingress router to new router identifier information; and updating a router mapping table with the new router identifier information.

20. The method of claim 19 further comprising: